Junglewise Threat Intelligence

CVE-2016-9243: PYSEC-2017-8 - HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.

CVE-2016-9243 · Severity: low · CVSS 3 · Published 2017-03-27

Technologies: cryptography (PyPI). Vendors: PyPI.

Executive brief

HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.

Affected products

  • PyPI cryptography

Related threats